Blockchain analytics firm Chainalysis reported Thursday that the number of instances in which attackers stored malware instructions or infrastructure data on public blockchains rose 420% over the past twelve months. The firm said the technique, called a blockchain dead drop (BDD), allows malicious payloads and command-and-control pointers to live inside on-chain transactions and smart contracts, making campaigns far harder to remove than those hosted on conventional servers or domains.
Chainalysis attributes roughly two of every three new dead-drop records as of the second quarter of 2026 to nation-state operators linked to North Korea and Iran. In one North Korea-tied campaign tracked by Google Threat Intelligence as UNC5342, infected devices were routed through Tron and Aptos transactions before converging on a single BNB Smart Chain transaction that held encrypted server addresses and configuration data. The report says this mirrors a 2025 operation in which North Korean hackers planted crypto-stealing code inside Ethereum-style smart contracts under the EtherHiding label.
Chainalysis also linked activity to Iran’s Ministry of Intelligence, saying operators encoded command-and-control routing data directly on the Bitcoin blockchain. The attackers allegedly sent tiny payments to a Bitcoin address with historical ties to Satoshi Nakamoto, using it as a permanent public reference point for infected machines. Since July 2025, malicious blockchain records have risen 440%, a jump that coincides with the spread of open-weight AI models capable of generating harmful code. Eric Jardine, Chainalysis cybercrimes research lead, said there is a “clear temporal association,” but the firm could not prove the actors actually used those models.
The findings add to broader concerns about state-sponsored crypto crime. CertiK has estimated that DPRK-linked actors have stolen about $6.75 billion since 2016 across 263 incidents, while separate Black Hat research found North Korean operators had infiltrated 1,640 companies in 57 countries. U.S. intelligence says stolen funds help finance Pyongyang’s nuclear and missile programs.